[Git][security-tracker-team/security-tracker][master] 3 commits: lts: wordpress not-affected in bullseye/bookworm (CVE-2026-60137)

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Thu Jul 23 23:27:12 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1147fd97 by Utkarsh Gupta at 2026-07-24T03:33:14+05:30
lts: wordpress not-affected in bullseye/bookworm (CVE-2026-60137)

- - - - -
15352b22 by Utkarsh Gupta at 2026-07-24T03:54:53+05:30
dla-needed: add exim4 for bullseye/bookworm

- - - - -
77a09e4c by Utkarsh Gupta at 2026-07-24T03:54:53+05:30
dla-needed: add bind9 for bookworm

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -7720,6 +7720,8 @@ CVE-2026-63030 (WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected
 	NOTE: The error handling in the problematic function is different in 6.8 and below.
 CVE-2026-60137 (WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0 ...)
 	- wordpress 7.0.2+dfsg1-1 (bug #1142510)
+	[bookworm] - wordpress <not-affected> (Vulnerable is_array-gated author__not_in handling introduced in 6.8; shipped version applies absint unconditionally)
+	[bullseye] - wordpress <not-affected> (Vulnerable is_array-gated author__not_in handling introduced in 6.8; shipped version applies absint unconditionally)
 	NOTE: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
 	NOTE: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
 	NOTE: https://github.com/WordPress/wordpress-develop/commit/74d37a344cbf28e9187a1a5ca71b33d186bcd333 (7.0.2)


=====================================
data/dla-needed.txt
=====================================
@@ -69,11 +69,12 @@ apache-log4j2/bullseye
 async-http-client (Chris Lamb)
   NOTE: 20260610: Added by Front-Desk (rouca)
 --
-bind9/bullseye (eamanu)
+bind9 (eamanu)
   NOTE: 20260520: Added by Front-Desk (Beuc)
   NOTE: 20260520: 6 new CVEs including 1 memory corruption, upcoming DSA (Beuc/front-desk)
   NOTE: 20260629: finishing backporting patches (eamanu)
   NOTE: 20260713: still in review (eamanu)
+  NOTE: 20260724: Also add for bookworm (9.18.49); 8/9 CVEs affecting. (utkarsh/front-desk)
 --
 bouncycastle
   NOTE: 20260417: Added by Front-Desk (rouca)
@@ -182,6 +183,10 @@ evolution-data-server/bookworm
   NOTE: 20260717: Added by Front-Desk (Beuc)
   NOTE: 20260717: Follow DLA-4503-1/bullseye (1 CVE) (Beuc/front-desk)
 --
+exim4
+  NOTE: 20260724: local privesc, exim <=4.99.4 affected, fixed in 4.99.5
+  NOTE: 20260724: EXIM-Security-2026-06-22.1 (High) and .3 (Medium) (utkarsh/front-desk)
+--
 expat
   NOTE: 20260518: Added by Front-Desk (Beuc)
   NOTE: 20260518: Upcoming DSA + many postponed CVE.



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/2aa28598db39484abf06f58981fb957f28543479...77a09e4c2cf7c7fe297f55ccb40be6338b27d15f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/2aa28598db39484abf06f58981fb957f28543479...77a09e4c2cf7c7fe297f55ccb40be6338b27d15f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260723/2f0cb42f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list